Redirect Vulnerability in IBM Security Access Manager
CVE-2017-1489
6.1MEDIUM
Summary
A redirect vulnerability exists in the e-community configurations of IBM Security Access Manager versions 6.1, 7.0, 8.0, and 9.0. This flaw allows the ECSSO Master Authentication to redirect users to an external server that is not part of the e-community domain. Such unauthorized redirection can pose significant security risks by potentially exposing sensitive user information to attackers who control the rogue servers. Proper security measures and updates are essential to mitigate this risk.
Affected Version(s)
Security Access Manager for Web 6.1
Security Access Manager for Web 6.1.1
Security Access Manager for Web 7.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved